Cyber-security firm Sophos is notifying customers via email about a security breach that took place earlier this week. The company became aware of the misconfiguration on November 24. The hackers exploited an SQL injection zero-day vulnerability to gain access to exposed XG devices. A Sophos spokesperson revealed that only a small subset of the companys customers were affected. At the time of writing the exact number of affected customers is still unknown. In April, the security firm released an emergency patch to address an. vulnerability affecting its XG Firewall product that has been exploited in the wild.”]
Source: https://securityaffairs.co/wordpress/111495/data-breach/sophos-data-leak.html

